CVE-2020-26983: Siemens JT2Go PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing PDF files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11900)
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens JT2Go. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26983?
CVE-2020-26983 is rated as a high severity vulnerability due to its potential for exploitation leading to an out of bounds write.
How do I fix CVE-2020-26983?
To fix CVE-2020-26983, upgrade Siemens JT2Go and Teamcenter Visualization to versions 13.1.0 or later.
What software is affected by CVE-2020-26983?
CVE-2020-26983 affects all versions of Siemens JT2Go and Teamcenter Visualization prior to version 13.1.0.
What risks does CVE-2020-26983 pose?
CVE-2020-26983 poses risks including potential data corruption and unauthorized access through exploitation of the vulnerability.
Is there a workaround for CVE-2020-26983?
There are currently no known workarounds for CVE-2020-26983 other than upgrading the affected software.